Loading
Set Up and Maintain Your Salesforce Organization
Encrypt Backup & Recover Next Data

Encrypt Backup & Recover Next Data

Your backups contain the same sensitive data that you encrypt in your production org. It makes sense to protect backups the same way. Shield Platform Encryption extends to Backup & Recover Next and encrypts backup data at rest with a root key that's unique to your org. As a result, your backup data meets the same compliance and regulatory requirements as your production data.

Required Editions

Available in both Lightning Experience and Salesforce Classic (not available in all orgs).
Available in: Enterprise, Performance, Unlimited, and Developer Editions. Requires purchasing Salesforce Shield or Shield Platform Encryption, and the Backup & Recover Data and Backup & Recover Files add-on licenses.

Encryption for Backup & Recover Next uses a two-tier key architecture. You control a Backup & Recover root key, which Salesforce then uses to protect the data encryption keys (DEKs) that encrypt data backups at rest. Generate your root key with Salesforce, or use Bring Your Own Key (BYOK) to generate a root key outside Salesforce and then upload it. Manage your root key in Setup or through the API, including key rotation. All Salesforce-generated and customer-supplied key material is visible on the Key Management page for auditing.

Note
Note Backup & Recover root keys encrypt backups made with Salesforce Backup & Recover Next. These root keys don’t encrypt data backups made with Backup & Recover for Salesforce or the legacy Salesforce Backup.

Your Backup & Recover root key encrypts all backups created after you activated your root key. Earlier backups remain unencrypted. If you’re new to Backup & Recover Next, generate a root key before your first backup.

 
Indlæser
Salesforce Help | Article